| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| Vulnerability in the Oracle Demand Signal Repository product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Demand Signal Repository. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Demand Signal Repository accessible data as well as unauthorized access to critical data or complete access to all Oracle Demand Signal Repository accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N). |
| IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper access control. |
| Vulnerability in the Oracle Demand Signal Repository product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Demand Signal Repository. Successful attacks of this vulnerability can result in takeover of Oracle Demand Signal Repository. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H). |
| Vulnerability in the Oracle Demand Signal Repository product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Demand Signal Repository. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Demand Signal Repository accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Demand Signal Repository. CVSS 3.1 Base Score 8.1 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H). |
| The User Private Files WordPress plugin before 2.2.0 does not properly protect its stored private files on multisite installations, where the rewrite rule it relies on to route file requests through its access check is never reached, allowing unauthenticated users to retrieve other users' private files directly. |
| Multiple ECH outer extension references are not permitted under RFC 9849; previously, a client could send a well-crafted packet that could trigger memory exhaustion in the server process by specifying multiple references. We now reject these as malformed and curb the memory amplification vector as a result. |
| Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Welcart Welcart e-Commerce usc-e-shop allows Reflected XSS.This issue affects Welcart e-Commerce: from n/a through 2.12.3. |
| Missing Authorization vulnerability in properfraction ProfilePress wp-user-avatar allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects ProfilePress: from n/a through 4.17.3. |
| Authentication Bypass by Spoofing vulnerability in Liquid Web / StellarWP GiveWP give allows Identity Spoofing.This issue affects GiveWP: from n/a through 4.16.8.1. |
| Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in jegtheme JNews - Pay Writer jnews-pay-writer allows Blind SQL Injection.This issue affects JNews - Pay Writer: from n/a through 12.0.1. |
| Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in VibeThemes WPLMS wplms allows Blind SQL Injection.This issue affects WPLMS : from n/a through 4.973. |
| Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in e4jvikwp VikBooking Hotel Booking Engine & PMS vikbooking allows Reflected XSS.This issue affects VikBooking Hotel Booking Engine & PMS: from n/a through 1.8.14. |
| Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Mamunur Rashid Classified Listing classified-listing allows Stored XSS.This issue affects Classified Listing: from n/a through 6.1.2. |
| Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Stiofan BlockStrap Page Builder - Bootstrap Blocks blockstrap-page-builder-blocks allows Reflected XSS.This issue affects BlockStrap Page Builder - Bootstrap Blocks: from n/a through 0.1.58. |
| Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Extend Themes Kubio AI Page Builder kubio allows Reflected XSS.This issue affects Kubio AI Page Builder: from n/a through 2.9.3. |
| Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeREX Education Center education allows Reflected XSS.This issue affects Education Center: from n/a through 3.6.12. |
| Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bracketweb Ogency ogency allows Reflected XSS.This issue affects Ogency: from n/a through 1.0.0. |
| Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Shinetheme Traveler traveler allows Blind SQL Injection.This issue affects Traveler: from n/a through 3.2.9. |
| A flaw was found in ansible-core. When installing a collection with
`ansible-galaxy collection install`, the archive extractor validates member
paths using lexical path normalisation (os.path.abspath) instead of resolving
symbolic links (os.path.realpath), and it performs no containment check on
symlink-typed directory members before creating them. A crafted collection
tarball can chain symlink directory entries so that a subsequent file member is
written outside the intended destination directory. This allows an attacker who
can get a victim to install a malicious collection to overwrite arbitrary files
with the privileges of the user running ansible-galaxy, leading to code
execution on the control node. This is a bypass of the fix for CVE-2020-10691. |
| IBM Guardium Data Protection 12.2 is vulnerable to a signature verification bypass in the patch installer. An attacker with local access could exploit this vulnerability to execute arbitrary code with root privileges. |